QUYFIN

Privacy Policy

Last updated: August 2026

QUYFIN – Research Observatory on Biodiversity Dynamics (“QUYFIN”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal data of visitors, collaborators, researchers, partners and other individuals who interact with our website and activities.

This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website, contact us, submit information through our online forms or otherwise interact with QUYFIN.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek and European data protection legislation.

1. Data Controller

The data controller responsible for the processing of personal data through this website is:

QUYFIN – Research Observatory on Biodiversity Dynamics
[Legal entity / Company name]
[Registered address]
Greece
Email: [contact@quyfin.com]
Website: [www.quyfin.com]

For any questions concerning this Privacy Policy or the processing of your personal data, you may contact us using the details above.

2. Personal Data We May Collect

Depending on how you interact with our website, we may collect the following categories of personal data:

Information you provide directly

When you contact us or submit a form, we may collect information such as:

Please avoid submitting sensitive personal information unless it is necessary for your communication with us.

Technical information

When you access our website, certain technical information may be processed automatically, including:

Some of this information may be collected through cookies or similar technologies, subject to your consent where required.

3. How We Use Personal Data

We may process personal data for the following purposes:

Personal data collected through the website will not be used for purposes incompatible with those described in this Privacy Policy.

4. Legal Basis for Processing

Under the GDPR, we process personal data only when a valid legal basis exists.

Depending on the circumstances, processing may be based on:

Consent – where you have given us permission to process your personal data for a specific purpose.

Legitimate interests – where processing is necessary for the legitimate operation, security, communication or development of QUYFIN, provided that these interests do not override your fundamental rights and freedoms.

Pre-contractual or contractual necessity – where processing is necessary in connection with a potential or existing collaboration, agreement or service.

Legal obligation – where processing is required to comply with applicable law or regulatory requirements.

Where processing is based on consent, you may withdraw your consent at any time.

5. Contact and Collaboration Forms

When you submit information through a contact, collaboration or project-related form on our website, the information you provide will be used primarily to review and respond to your request.

Depending on the nature of your enquiry, your information may be shared internally with the appropriate members of the QUYFIN team.

Submitting a form does not automatically create a contractual, research or commercial relationship with QUYFIN.

6. Research and Biodiversity Data

QUYFIN’s activities may involve the collection and analysis of ecological, environmental, agricultural and biodiversity data.

Such information may include observations relating to plant populations, insect populations, pollinator behaviour, soil characteristics, microbial communities, geographic areas and ecological interactions.

Environmental and biodiversity data does not necessarily constitute personal data under the GDPR. However, where research or monitoring information can be associated with an identifiable individual, farm operator, landowner, collaborator or other natural person, QUYFIN will process that information in accordance with applicable data protection requirements.

Specific research projects may be governed by additional privacy notices, research protocols, agreements or consent procedures where appropriate.

7. Cookies and Similar Technologies

Our website may use cookies and similar technologies to ensure proper functionality, improve performance, understand website usage and, where applicable, provide analytics services.

Cookies may include:

Where required by law, non-essential cookies will only be activated after you provide your consent.

You may modify or withdraw your cookie preferences at any time through the cookie settings available on the website.

For more information, please refer to our Cookie Policy, where available.

8. Third-Party Services

Our website may use third-party technology providers for services such as:

Where these providers process personal data on our behalf, we take reasonable steps to ensure that appropriate contractual and technical safeguards are in place.

Some third-party services may process data outside the European Economic Area (“EEA”). Where this occurs, appropriate safeguards will be implemented where required by applicable data protection law.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected.

The appropriate retention period depends on the nature of the information, the purpose of processing and any applicable legal, contractual or research requirements.

Contact and enquiry information may be retained for a reasonable period to allow us to manage communications, maintain appropriate records and follow up on potential collaborations.

Where personal data is no longer required, it will be deleted, anonymised or securely archived where legally necessary.

10. Data Security

QUYFIN takes appropriate technical and organisational measures designed to protect personal data against:

While we take reasonable measures to protect information, no internet-based system or electronic storage method can guarantee absolute security.

11. Your Rights Under the GDPR

If the GDPR applies to the processing of your personal data, you may have the right to:

The exercise of certain rights may be subject to conditions or limitations established by applicable law.

To exercise your rights, please contact us at:

[privacy@quyfin.gr]

We may need to verify your identity before responding to certain requests.

12. Supervisory Authority

You have the right to lodge a complaint with the competent supervisory authority if you believe that your personal data has been processed in violation of applicable data protection legislation.

In Greece, the competent authority is the:

Hellenic Data Protection Authority (HDPA)
Athens, Greece

13. Links to External Websites

Our website may contain links to websites operated by universities, research institutions, public authorities, project partners or other third parties.

QUYFIN is not responsible for the privacy practices, security or content of external websites.

We encourage you to review the privacy policies of any third-party website you visit.

14. Children’s Privacy

The QUYFIN website is not intended to knowingly collect personal data from children through its general contact or collaboration services.

Where a specific educational, citizen-science or research activity involves minors, appropriate privacy information, consent procedures and safeguards will be implemented separately where required.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our activities, website functionality, technologies or applicable legal requirements.

The latest version will always be published on this page together with the date of the most recent update.

16. Contact Us

For questions about this Privacy Policy, the processing of your personal data or the exercise of your data protection rights, please contact:

QUYFIN – Research Observatory on Biodiversity Dynamics
Email: [contact@quyfin.com]
Website: [www.quyfin.com]